Job Closed
This listing is no longer active.
Information Technology Security Engineer
Location
United States
Posted
109 days ago
Salary
0
Seniority
Mid Level
Job Description
Information Technology Security Engineer
The Heritage Group
About The Heritage Group The Heritage Group is a fourth-generation, family-owned business focused on construction and materials, environmental services and specialty chemicals. Over the last 90+ years, the Heritage portfolio has grown to include more than 50 companies that employ more than 6,000 people. What unites this diverse group of businesses and individuals is our commitment to create a safer, more enriching, and sustainable world by harnessing the power of family. The IT Security Engineer is responsible for maintaining security operations and assisting ITSS with security-related projects, designed to protect the company's sensitive data and assets. Responsibilities include safeguarding system perimeters, enhancing security measures for both cloud-based and on-premises infrastructures, managing network security devices and associated security tools, and responding to security incidents. The IT Security Engineer is responsible for assisting with the design, implementation, and evaluation of security solutions, while also overseeing the performance of current systems. The role is a member of the IT shared services team that supports a portfolio of privately held companies. *This position is remote, with occasional travel to the Indianapolis, IN area. Qualified candidates must currently reside in the Eastern or Central time zones.* Essential Functions - Design, execute, and oversee security measures to safeguard computer systems, networks, and data. - Identify security vulnerabilities, promote system security best practices, and collaborate with teams for mitigation implementation. - Security awareness training and phishing simulation campaigns. - Contribute to the design of the system security architecture. - Assist with preparing and documenting standard operating procedures and protocols. - Audit compliance with company security standards and work with team(s) to remedy noncompliance - Configure, optimize, and troubleshoot security infrastructure devices. - Utilize current system security tools to provide security remediation recommendations and guidance to business units and ITSS teams. - Research and review new technical solutions and security tools to help mitigate security vulnerabilities and automate repeatable tasks. - Detect, investigate, and respond to security incidents with rapid communication to stakeholders. - Write comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement. - Be an essential part of executing all tasks or projects as put forth in the IT security strategic plan. - Conduct vulnerability assessments and security testing on systems, networks, and applications to identify weaknesses. - Effectively communicate security risks to both technical and non-technical colleagues, highlighting potential impacts and required actions. - Stay updated with the latest trends in cybersecurity threats, and mitigation techniques. - Additional duties and responsibilities as assigned, including but not limited to continuously growing in alignment with the Company’s core values, competencies, and skills. - Education Qualifications - Required Bachelor's Degree degree in Computer Science or related field or equivalent work experience Experience Qualifications - Required minimum of 3-5 years of proven work experience as an IT Security Engineer or similar role - Required experience in building and maintaining security systems. Experience with Microsoft security solutions including Sentinel, Azure Information Protection, Defender for Cloud Apps, etc. is highly preferred. - Required detailed technical knowledge of database and operating system security. - Required hands-on experience in security systems, including firewalls, intrusion detection and prevention systems, anti-virus software, authentication systems, log management, content filtering, etc. (Sophos, Palo Alto, Azure SSO, and LogScale preferred). - Required experience with network technologies and with system, security, and network monitoring tools (Cisco, Aruba, and Netskope preferred). - Thorough understanding of the latest security principles, techniques, and protocols. - Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocols. Skills and Abilities - Very high-level of self-awareness and desire to develop leadership capabilities. - Ability to hold themselves and others accountable to high standards. - Experience identifying and resolving issues independently. Demonstrates a solid sense of accountability and sound personal judgement. - Proven analytical skills with information systems and security systems. - Courage to take initiative in unfamiliar or ambiguous circumstances. - Ability to gain alignment with different clients and represent a common point of view across multiple stakeholders. Must be confident building business partnerships with various business stakeholders. - Excellent verbal and written communication - Problem solving skills and the ability to work under pressure. - Maintains a high level of confidentiality. Licenses and Certifications - Certified Information Systems Security Professional (CISSP) - Global Knowledge or equivalent certifications Required - Microsoft Azure certifications Preferred Working Conditions/Physical Demands - Ability to travel locally and across business sites as needed. - Office and remote environments, up to 8 hours working behind a computer. - Ability to participate in on-call rotation. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. #TheHeritageGroup
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Processing Clerk
The Shella FoundationThe Shella Foundation is a nonprofit organization dedicated to enhancing the lives of seniors, children, veterans, and individuals with disabilities. Through strategic grants, community partnerships, and fundraising initiatives, we empower individuals to live independently in their homes. Our work also inspires families to advocate for accessible, high-quality care and supportive services, ensuring that those in need receive the respect and assistance they deserve.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are seeking a detail-oriented and reliable Remote Information Processing Clerk to join our team. In this role, you will be responsible for entering, updating, organizing, and maintaining information in company systems. This is a fully remote position that requires strong attention to detail, accuracy, and basic computer skills. - Enter and update data into company databases and systems - Review information for accuracy and completeness - Correct errors and report inconsistencies - Organize digital files and maintain proper records - Respond to internal requests for information - Follow data privacy and confidentiality guidelines - Meet daily or weekly productivity targets - Communicate with team members via email or chat Qualifications - High school diploma or equivalent - Basic computer skills (Microsoft Office, Google Workspace, or similar tools) - Strong typing skills and attention to detail - Good written communication skills - Ability to work independently and manage time effectively - Reliable internet connection and personal computer - Previous data entry or administrative experience (preferred but not required) Requirements - High school diploma or equivalent - Basic computer skills (Microsoft Office, Google Workspace, or similar tools) - Strong typing skills and attention to detail - Good written communication skills - Ability to work independently and manage time effectively - Reliable internet connection and personal computer - Previous data entry or administrative experience (preferred but not required) Benefits - 100% remote work (work from home) - Flexible schedule options - Competitive hourly pay - Paid training provided
Analista SR de Ciber Segurança – Pentest
Vivo (Telefônica Brasil)Com a conexão, queremos que você descubra novos pontos de vista e aproveite tudo o que realmente importa.
• O profissional será responsável por colaborar com a equipe de Red Team e executar tarefas de segurança ofensiva para garantir a proteção das aplicações e infraestrutura da empresa. • Planejar e executar testes de invasão em sistemas internos e externos, incluindo infraestrutura, cloud, containers, aplicações web, apps mobile e APIs/webservices; • Auxiliar nas tarefas de hardenização de servidores, sistemas operacionais e serviços com as equipes de infraestrutura; • Participar da resposta a incidentes com o CSIRT, investigando ameaças e colaborando nas correções de vulnerabilidades; • Auxiliar nas interações com as equipes de Threat Intel; • Planejar e executar exercícios de Red Team, envolvendo Blue Team e com suporte das equipes de Threat Intel; • Propor novas soluções de segurança com base nas tendências de mercado; • Realizar provas de conceito (PoC) e implementar novas ferramentas para melhorar os processos da segurança ofensiva; • Elaborar relatórios e apresentações técnicas (documentação e evidência dos testes executados) para os times internos e gerenciais.
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! . See yourself at Twilio Join the team as Twilio’s next Senior Manager of Offensive Security. About the job As the Senior Manager of Offensive Security and Red Teaming, you will lead an elite team of ethical hackers and security penetration testers dedicated to proactively uncovering and mitigating vulnerabilities across the enterprise and our products. You are a technical expert and a strategic leader. You will design and oversee sophisticated adversary emulation exercises that challenge our defenses, ensuring that our security team and overall security posture are prepared for real-world threats. Responsibilities In this role, you’ll: - Strategic Leadership: Develop and execute a multi-year roadmap for offensive security, including red teaming, penetration testing, bug bounty, and vulnerability research. - Adversary Emulation: Design and lead full-scope red team engagements that simulate Advanced Persistent Threats (APTs) to test detection and response capabilities. - Program Management: Oversee the end-to-end lifecycle of offensive engagements, from initial scoping and Rules of Engagement (RoE) to final reporting. - Purple Teaming: Facilitate collaborative "Purple Team" exercises with Detection and Response (TDR) to improve detection logic and incident response playbooks. - Executive Communication: Translate complex technical findings into actionable business risk assessments for C-suite executives and Board members. - Team Mentorship: Recruit, retain, and develop a high-performing team of offensive security engineers, providing technical guidance and career coaching. - Vulnerability Management Integration: Partner with vulnerability management, product, and engineering to ensure that findings from offensive tests are prioritized and remediated effectively. - Tooling & Automation: Oversee the development of custom scripts, payloads, and C2 (Command and Control) frameworks to enhance the team’s stealth and efficiency. - Adversarial AI Testing: Conduct specialized threat modeling for AI-native applications, focusing on the OWASP Top 10 for LLMs and MITRE ATLAS (Adversarial Threat Landscape for AI Systems). - AI attacks and mitigations: Design and execute manual and automated Prompt Injection & Jailbreaking to bypass model guardrails, system prompts, and safety filters. - Regulatory Compliance: Ensure all offensive activities align with legal, ethical, and regulatory standards (e.g., GDPR, SOC2, PCI-DSS). - Threat Intelligence Integration: Incorporate current Cyber Threat Intelligence (CTI) into attack scenarios to ensure they reflect the latest real-world TTPs (Tactics, Techniques, and Procedures). - Third-Party Oversight: Manage relationships and quality control for external security consultancy firms performing third-party penetration tests. - Research & Development: Encourage and lead research into emerging technologies to identify future attack vectors. - Cross-Functional Collaboration: Work closely with Product and Engineering teams to bake security into the Software Development Life Cycle (SDLC) through testing and assessments Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! *Required: - Experience: Minimum of 10+ years in cybersecurity, with at least 5 years specifically in offensive security roles and 2+ years in a leadership or management capacity. - Technical Expertise: Deep knowledge of security frameworks like the MITRE ATT&CK framework, Cyber Kill Chain, and advanced exploitation techniques (e.g., AD, cloud, and applications attacks). - Certifications: Possession of advanced industry certifications such as OSCP, OSEP, OSWE, GXPN or similar - Infrastructure Knowledge: Proficient in attacking and defending diverse environments including AWS/Azure/GCP, Kubernetes, and hybrid-cloud architectures. - Hands-on AI Testing: Proven experience in automating red teaming for GenAI and proficiency in using AI offensive tools like PyRIT, Prompfoo, Xbow or Counterfit to build and stage AI powered attacks - Tooling Proficiency: Advanced experience with red team and penetration testing tools such as Cobalt Strike, Burp Suite Pro, Metasploit, BloodHound, and Sliver. - Programming Skills: Strong ability to code or script in Python, PowerShell, Go, or C++ for exploit development and task automation. - Analytical Thinking: Proven ability to connect individual vulnerabilities into complex attack chains that demonstrate significant business impact. - Ethical Integrity: A flawless record of ethical conduct and the ability to handle extremely sensitive access and information with total discretion. Desired: - Telecom expertise is preferred Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA. Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Compensation *Please note the salary range information provided applies only to candidates residing in California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State due to local requirements. Compensation for candidates in other locations will be discussed during the hiring process. Please note that hiring for this role is not restricted to the locations listed above. The estimated pay ranges for this role are as follows: - Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $188, 240 - 235,300. - Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $199,280 - 249,100. - Based in the San Francisco Bay area, California: $221,360 - $276,700. - This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location. Applications for this role are intended to be accepted until May 21st 2026, but may change based on business needs. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.
• Conduct detailed investigations on high-complexity incidents • Work directly with the Incident Response Manager and cross-functional teams • Develop and maintain technical playbooks • Provide technical guidance and mentorship to junior analysts


